GeoDA: A Geometric Framework for Black-Box Adversarial Attacks
Ali Rahmati, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, Huaiyu Dai
Abstract
Adversarial examples are known as carefully perturbed images fooling image classifiers. We propose a geometric framework to generate adversarial examples in one of the most challenging black-box settings where the adversary can only generate a small number of queries, each of them returning the top-1 label of the classifier. Our framework is based on the observation that the decision boundary of deep networks usually has a small mean curvature in the vicinity of data samples. We propose an effective iterative algorithm to generate query-efficient black-box perturbations with small p norms for p ≥ 1, which is confirmed via experimental evaluations on state-of-the-art natural image classifiers. Moreover, for p = 2, we theoretically show that our algorithm actually converges to the minimal 2perturbation when the curvature of the decision boundary is bounded. We also obtain the optimal distribution of the queries over the iterations of the algorithm. Finally, experimental results confirm that our principled black-box attack algorithm performs better than state-of-the-art algorithms as it generates smaller perturbations with a reduced number of queries. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 85904c23-8446-421b-9780-45c1e7d2083bCited by top-tier papers27
- Hold me tight! Influence of discriminative features on deep network boundariesGuillermo Ortiz-Jiménez, Apostolos Modas, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardNeurIPS 2020 · 53 citations
- DeHiB: Deep Hidden Backdoor Attack on Semi-supervised Learning via Adversarial PerturbationZhicong Yan, Gaolei Li, Yuan Tian, Jun Wu et al.AAAI 2021 · 43 citations
- Boosting Black-Box Attack with Partially Transferred Conditional Adversarial DistributionYan Feng, Baoyuan Wu, Yanbo Fan, Li Liu et al.CVPR 2022 · 34 citations
- CGBA: Curvature-aware Geometric Black-box AttackMd Farhamdur Reza, Ali Rahmati, Tianfu Wu, Huaiyu DaiICCV 2023 · 33 citations
- Exploring Effective Data for Surrogate Training Towards Black-box AttackXuxiang Sun, Gong Cheng, Hongda Li, Lei Pei et al.CVPR 2022 · 26 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- On the Design of Black-Box Adversarial Examples by Leveraging Gradient-Free Optimization and Operator Splitting MethodPu Zhao, Sijia Liu, Pin-Yu Chen, Nghia Hoang et al.ICCV 2019 · 61 citations
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 55 citations
Related papers
- BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the WildJie Wan, Jianhao Fu, Lijin Wang, Ziqi YangS&P 2024 · 13 citations
- SurFree: A Fast Surrogate-Free Black-Box AttackThibault Maho, Teddy Furon, Erwan Le MerrerCVPR 2021
- Finding Optimal Tangent Points for Reducing Distortions of Hard-label AttacksChen Ma, Xiangyu Guo, Li Chen, Jun-Hai Yong et al.NeurIPS 2021 · 24 citations
- Simple and Efficient Hard Label Black-box Adversarial Attacks in Low Query Budget RegimesSatya Narayan Shukla, Anit Kumar Sahu, Devin Willmott, J. Zico KolterKDD 2021 · 24 citations
- ADBA: Approximation Decision Boundary Approach for Black-Box Adversarial AttacksFeiyang Wang, Xingquan Zuo, Hai Huang, Gang ChenAAAI 2025 · 14 citations
